s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3 high

📛 Threat Title

Unknown: SOLICITUD DE COTIZACION.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 1011200 bytes. Tags: exe. Reporter: James_inthe_box. First seen: 2026-05-14 11:13:34.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain cotizacion.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/cotizacion.exe

IOC database

Type
domain
Value
cotizacion.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/cotizacion.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
650 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
1 feed

IOC database

Type
hash_sha256
Value
490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3

hash_sha1 6b7d1a14e7f0f6cd807e4602b79d31ca1d69789e VT 50 / 75 1 feed

IOC database

Type
hash_sha1
Value
6b7d1a14e7f0f6cd807e4602b79d31ca1d69789e
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Basic.C5882397
Alibaba malicious TrojanPSW:MSIL/Agensla.fe959f6e
alibabacloud malicious Trojan[stealer]:MSIL/Kepavll.Gen
ALYac malicious Trojan.GenericKD.80143150
Antiy-AVL malicious Trojan[PSW]/MSIL.Agensla
APEX malicious Malicious
Arcabit malicious Trojan.Generic.D4C6E32E
Avast malicious Win32:MalwareX-gen [Misc]
AVG malicious Win32:MalwareX-gen [Misc]
Avira malicious TR/W32.Agent
BitDefender malicious Trojan.GenericKD.80143150
Bkav malicious W32.Malware.62BB9397
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious BackDoor.XWormNET.9
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.80143150 (B)
ESET-NOD32 malicious MSIL/Kryptik.AQEA trojan
F-Secure malicious Trojan.TR/W32.Agent
Fortinet malicious MSIL/Formbook.AA!tr
GData malicious Trojan.GenericKD.80143150
Google malicious Detected
huorong malicious Trojan/MSIL.Injector.nj
K7AntiVirus malicious Password-Stealer ( 005ce0261 )
K7GW malicious Password-Stealer ( 005ce0261 )
Kingsoft malicious MSIL.Trojan-PSW.Agensla.gen
Lionic malicious Trojan.Win32.Agensla.i!c
Malwarebytes malicious Malware.AI.4254202813
McAfeeD malicious Trojan:Win/XWorm.NEN
Microsoft malicious Trojan:Win32/Kepavll!rfn
MicroWorld-eScan malicious Trojan.GenericKD.80143150
Paloalto malicious generic.ml
Panda malicious Trj/Agent.JMU
Rising malicious Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:GlKEwH8t0dzlMSqaoFlInw)
Sangfor malicious Infostealer.Msil.AgentTesla.Vh17
SentinelOne malicious Static AI - Suspicious PE
Sophos malicious Mal/Generic-S
Symantec malicious MSIL.Packed.12
Tencent malicious Msil.Trojan.LummaStealer.Dnhl
Trapmine malicious malicious.moderate.ml.score
TrendMicro malicious Trojan.MSIL.MSILZILLA.TL0101EE26ZZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/MSIL_Agent.KBL.gen!Eldorado
VBA32 malicious Malware-Cryptor.MSIL.Fuzzy.Heur
VIPRE malicious Trojan.GenericKD.80143150
VirIT malicious Trojan.Win32.MSIL_Heur.A
ViRobot malicious Trojan.Win.Z.Kryptik.1011200.A
Yandex malicious Trojan.Igent.b6xFOk.1

Details From VirusTotal

Basic Properties
MD52c3386eef926e484cd7ca46cad396a9b
SHA-16b7d1a14e7f0f6cd807e4602b79d31ca1d69789e
SHA-256490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3
VHash216036651512f087383e6460
SSDEEP12288:ShKreek9DMYBUwo92piHlMmau1ouSl1rFumN2H8+9VL72BwzupW9:SX2PCmQui1rBgc+9jR
TLSHT1E625BF2D368F884DD591EB788F3337D41770D47258F2D3567F8C5338AA2AAE59A8C242
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size987.5 KB
History
Creation date2025-02-26 01:47 UTC
First seen on VirusTotal2026-05-13 14:02 UTC
Last submission2026-05-14 11:15 UTC
Last analysis2026-06-13 06:01 UTC
Last modified on VirusTotal2026-06-20 02:56 UTC
Known Names
  • 223532X.exe
  • powerpoint.exe
  • SOLICITUD DE COTIZACIÓN.exe
  • COTIZACIÓN TEK_Quality.exe
  • _490644b09dd5e68cfea06b6380672071ec83ae4a04dcbb1a61322dcabdf9e0d3.exe
  • COTIZACI N TEK_Quality.exe
  • g7fk0tvha.exe
hash_md5 2c3386eef926e484cd7ca46cad396a9b VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2c3386eef926e484cd7ca46cad396a9b
2 feeds

IOC database

Type
hash_md5
Value
2c3386eef926e484cd7ca46cad396a9b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2c3386eef926e484cd7ca46cad396a9b

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 1011200 bytes. Tags: exe. Reporter: James_inthe_box. First seen: 2026-05-14 11:13:34.

Remediations (8)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.